CVE-2025-26634

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 122

Summary

CVE-2025-26634 is a critical vulnerability affecting Windows Core Messaging. This issue involves a heap-based buffer overflow, which can be exploited by an attacker who has already gained authorized network access. By sending specially crafted messages to a vulnerable system, the attacker can cause the buffer to overflow, resulting in unintended code execution and potential privilege escalation. This vulnerability poses a significant risk to systems that rely on Windows Core Messaging and have not been appropriately patched.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft